CMMC Level 2 assessment preparation

    Getting small defense contractors ready for a CMMC Level 2 assessment

    We do the technical implementation in Microsoft 365 and Intune, and build the evidence your assessor will ask to see.

    Book a scoping call
    110

    Security controls

    Each one has to be implemented and evidenced.

    14

    Control families

    From Access Control to System & Information Integrity.

    1

    Small team doing it all

    Most small businesses have no one whose job this is.

    Where most small contractors get stuck

    These four problems account for most of the delay and rework we see.

    No defined CUI boundary

    Nobody has written down where Controlled Unclassified Information actually lives, so the scope of the work keeps changing and the cost keeps growing.

    Unmanaged endpoints outside Intune

    Laptops on the shop floor, a shared machine in the office, or a personal device pulling email. If a device is not managed, its settings cannot be proven.

    No evidence trail for controls already in place

    The setting is turned on, but there is no export, screenshot, or report showing it is on and has stayed on. An assessor cannot accept what you cannot show.

    Treating it as paperwork instead of configuration

    A policy document that says devices are encrypted does not encrypt devices. Most of this work happens in the tenant, not in a binder.

    What we implement

    Each item below is a configuration project with a defined end state and evidence you can hand to an assessor.

    How the work maps to the control families

    Every CMMC Level 2 family is either configured by us, documented with your governance partner, or both. Control counts are from NIST SP 800-171.

    Control familyControlsWhat KBTS doesType
    ACAccess Control
    22Entra ID roles, Conditional Access, least-privilege file accessConfiguration
    ATAwareness & Training
    3Security awareness training rollout and completion recordsBoth
    AUAudit & Accountability
    9Microsoft 365 audit logging, retention, log review reportsConfiguration
    CMConfiguration Management
    9Intune baselines, app control, change recordsConfiguration
    IAIdentification & Authentication
    11MFA enforcement, password policy, device identityConfiguration
    IRIncident Response
    3Alerting and response runbooks; plan owned with your vCISOBoth
    MAMaintenance
    6Patching, remote maintenance controls, maintenance recordsConfiguration
    MPMedia Protection
    9BitLocker with escrowed keys, removable media restrictionsConfiguration
    PSPersonnel Security
    2Onboarding and offboarding account proceduresBoth
    PEPhysical Protection
    6Documented by your vCISO; we support device inventoryDocumentation
    RARisk Assessment
    3Vulnerability scanning and remediation reportingConfiguration
    CASecurity Assessment
    4Evidence packages; SSP and POA&M owned by your vCISOBoth
    SCSystem & Communications Protection
    16Email security, DNS filtering, encryption in transit, network segmentationConfiguration
    SISystem & Information Integrity
    7Defender for Endpoint, monitoring, update managementConfiguration

    Control counts are from NIST SP 800-171 Revision 2, the revision CMMC Level 2 is currently based on.

    Everything tracked in one place

    The governance side runs a compliance platform that maps every tool and configuration we deploy to the specific NIST SP 800-171 controls it satisfies. You see progress against all 110 controls instead of a spreadsheet nobody trusts.

    • Maps each control to the system that satisfies it
    • Tracks implementation status across all 110 controls
    • Generates and maintains the System Security Plan
    • Manages the Plan of Action and Milestones
    • Keeps the SPRS score current as work lands
    • Collects evidence in the form an assessor expects

    How we work with your assessor

    Two different jobs, handled by two different teams, so nothing falls between them.

    Governance is handled separately

    Our governance partner acts as your vCISO and owns the written side of the program: scoping the CUI boundary, writing the System Security Plan, maintaining the POA&M, drafting policy, and running the readiness assessment before you engage a C3PAO. KBTS stays in its lane: configuring the systems and producing the evidence that supports what they document.

    KBTS handles implementation and evidence

    We configure the systems the plan describes, in Microsoft 365, Intune, and on your devices. Then we produce the reports, exports, and records that show each control is in place and staying in place, so the plan and the systems match.

    Depending on what your contract requires, CMMC Level 2 is either self-assessed by the contractor or assessed by a C3PAO, an independent third-party assessment organization. KBTS does not certify anyone. We prepare your configuration and evidence for either path.

    Your IT provider is in scope too

    Under CMMC, a managed service provider that stores, processes, or transmits Controlled Unclassified Information on a contractor's behalf, or that provides security protection for it, falls inside the assessment scope. An assessor will ask about your IT provider.

    KBTS has addressed its own environment and can document how we access and support your systems. Most providers have not considered this and it surfaces late, during assessment.

    What we have already done

    Configuration running in production today, not a methodology slide.

    Five defense supply-chain tenants

    Currently running these baselines in production under active CMMC Level 2 preparation.

    Deployed across every managed endpoint

    Device baselines, encryption, and access policy applied and verified on every enrolled Windows device across those tenants.

    Every setting proven, not assumed

    A policy can be saved and still not apply. We verify each control landed on every enrolled device and produce the export or report that shows it, which is the part an assessor actually asks for.

    Common questions

    Start with a scoping call

    Tell us what your contract requires and what you have today. We will tell you what the work looks like before you commit to anything.

    Based in Plainville, Connecticut. Working with defense contractors across New England.